Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-2784

23
FAUCET Score

CVE-2025-2784 is a heap buffer over-read vulnerability in libsoup, specifically within the skip_insight_whitespace() function, allowing libsoup clients to read one byte out-of-bounds when processing crafted HTTP responses from a server. This flaw affects products like gnome and redhat. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring no user interaction, and potentially leading to limited confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.6.5CPE matchmatch criteria
cpe:2.3:a:gnome:libsoup:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:a:redhat:codeready_linux_builder:10.0:*:*:*:*:*:*:*
10.0_aarch64CPE matchmatch criteria
cpe:2.3:a:redhat:codeready_linux_builder_for_arm64:10.0_aarch64:*:*:*:*:*:*:*
10.0_aarch64CPE matchmatch criteria
cpe:2.3:a:redhat:codeready_linux_builder_for_arm64_eus:10.0_aarch64:*:*:*:*:*:*:*
10.0_s390xCPE matchmatch criteria
cpe:2.3:a:redhat:codeready_linux_builder_for_ibm_z_systems:10.0_s390x:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.79%
Probability of exploitation in next 30 days
EPSS Percentile
52.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0079 is in the 33rd percentile among its peer group of 23,703 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (22)

microsoftpatch availablevia msrc
Product: 19402-17084Fixed in: 3.4.4-5
microsoftpatch availablevia msrc
Product: 20113-17086Fixed in: 3.0.4-5
microsoftpatch availablevia msrc
Product: 19401-16823Fixed in: 3.0.4-5
microsoftpatch availablevia msrc
Product: 19446-17084Fixed in: 3.4.4-5
microsoftpatch availablevia msrc
Product: cbl2 libsoup 3.0.4-6 on CBL Mariner 2.0Fixed in: 3.0.4-5
microsoftpatch availablevia msrc
Product: cbl2 libsoup 3.0.4-5 on CBL Mariner 2.0Fixed in: 3.0.4-5
microsoftpatch availablevia msrc
Product: azl3 libsoup 3.4.4-6 on Azure Linux 3.0Fixed in: 3.4.4-5
microsoftpatch availablevia msrc
Product: azl3 libsoup 3.4.4-5 on Azure Linux 3.0Fixed in: 3.4.4-5
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: libsoup-0:2.62.3-2.el8_6.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: libsoup-0:2.62.3-2.el8_6.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: libsoup-0:2.62.3-3.el8_8.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: libsoup-0:2.72.0-10.el9_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: libsoup-0:2.72.0-8.el9_0.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: libsoup-0:2.72.0-8.el9_2.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: libsoup-0:2.72.0-8.el9_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: libsoup3-0:3.6.5-3.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: libsoup-0:2.62.2-9.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: libsoup-0:2.62.2-6.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libsoup-0:2.62.3-9.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: libsoup-0:2.62.3-1.el8_2.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: libsoup-0:2.62.3-2.el8_4.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: libsoup-0:2.62.3-2.el8_6.5
View patch

Vendor Advisories (2)

microsoft2025-Apr/CVE-2025-2784Important

Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content

Apr 8, 2025
redhatCVE-2025-2784Moderate

libsoup: Heap buffer over-read in `skip_insignificant_space` when sniffing content

Mar 25, 2025

References

lists.debian.org / debian-lts-announce/2025/04/msg00036.html
access.redhat.com / errata/RHSA-2025:21657
access.redhat.com / errata/RHSA-2025:7505
Third Party Advisory
access.redhat.com / errata/RHSA-2025:8126
Third Party Advisory
access.redhat.com / errata/RHSA-2025:8132
Third Party Advisory
access.redhat.com / errata/RHSA-2025:8139
Third Party Advisory
access.redhat.com / errata/RHSA-2025:8140
Third Party Advisory
access.redhat.com / errata/RHSA-2025:8252
Third Party Advisory
access.redhat.com / errata/RHSA-2025:8480
Third Party Advisory
access.redhat.com / errata/RHSA-2025:8481
Third Party Advisory
access.redhat.com / errata/RHSA-2025:8482
Third Party Advisory
access.redhat.com / errata/RHSA-2025:8663
Third Party Advisory
access.redhat.com / errata/RHSA-2025:9179
Third Party Advisory
access.redhat.com / security/cve/CVE-2025-2784
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Third Party Advisory
gitlab.gnome.org / GNOME/libsoup/-/issues/422
ExploitIssue Tracking